Skip to content

Changelog

All notable changes to this project are documented here. The format follows Conventional Commits and this file is generated by git-cliff from the release workflow.

1.7.0 - 2026-10-08

Features

  • examples: Real projects for every non-pixi reader, written by the real tools (#363) (74a5660)
  • input: Read pylock.toml (PEP 751) (#364) (aaa8ef0)
  • input: Read uv.lock, and find it by the upward search (#366) (bd098da)
  • input: Read poetry.lock (lock-version 2.x) (#367) (25abba3)
  • input: Read pdm.lock (lock_version 4.x) (#368) (5c65fff)
  • input: Read conda-lock.yml (unified, version 1) (#369) (2b82c59)
  • input: Read explicit conda spec files (#370) (371cf6d)
  • manifest: Declared dependencies beside non-pixi lockfiles (#371) (5978b18)
  • pypi: Record Python extras as pixi:python-extras and pixi:via-extra (#372) (5f4599b)
  • format: Dependency groups as CycloneDX scope and SPDX dev/optional relationships (#373) (632819a)
  • prefix: Describe plain venvs and site-packages, not only conda environments (#374) (acee39e)
  • prefix: Mark user-requested packages as direct from REQUESTED (#376) (9e22091)
  • prefix: --infer-extras for venvs, labelled as inferred (#377) (7060a59)
  • discover: Find every supported lockfile kind in the upward search and --scan (#378) (8e71644)
  • diff: --against accepts every supported lockfile, for venv drift checks (#379) (447359b)
  • Pre-commit hooks for writing the SBOM and the license gate (#382) (916524b)
  • action: Prefix and from-sbom inputs, and a tested example for uv projects (#383) (e85cfc9)

Bug Fixes

  • format: Lifecycle phase from the input, not always pre-build (#365) (a6a61e6)
  • purl: VCS, local and editable installs no longer claim a PyPI purl (#375) (b1053f0)
  • test: The never-consulted cache test no longer races the stale test (#387) (a3a7f9d)
  • release: Attach the wheels to the release deterministically (#388) (28cfefc)

Documentation

  • Using pixi-sbom without pixi, and a README that says what it reads (#385) (908f942)
  • How to get a lockfile pixi-sbom reads, for every common setup (#390) (ecbc6c2)
  • The Pipenv route is for Pipenv-managed projects; a pip venv uses --prefix (#391) (98bb4b8)

Testing

  • Every report, enrichment and gate on every input kind (#384) (83b4166)

1.6.0 - 2026-10-07

Features

  • vex: Machine-readable justification for not_affected assessments (#338) (e0ab8a9)
  • vex: Write analysis.response, and say why the assessment dates are not (#350) (aeb6b0b)
  • Default --conda-index-kind to prefix; anaconda stays selectable (#356) (84f9ff6)

Bug Fixes

  • Let the changelog span prereleases instead of fragmenting on them (#316) (7c9f50e)
  • vex: Refuse --vex with --format spdx instead of writing a VEX that links nowhere (#320) (adcf8e9)
  • Batched prefix.dev queries never exceed --concurrency (#355) (907d389)
  • Show --report outdated progress while prefix.dev batches are in flight (#359) (e02772c)
  • Count a batched package as soon as its batch lands (#360) (6a23b9f)

Documentation

  • Why the two conda index kinds disagree on dates, and on the newest hours (#352) (b62c0ed)

Testing

  • A local HTTP server, so request behaviour is asserted rather than timed by hand (#351) (86db1a8)

1.5.0 - 2026-10-04

Features

  • Retry a rate limit, and stop reporting an unasked index as no upstream (#304) (c3b352b)
  • Add --concurrency and a concurrency configuration key (#307) (c2bc82e)
  • Say in --doctor how many requests and which conda index (#308) (729812d)

Bug Fixes

  • Count the network a run used, not the network it could have used (#300) (991b517)
  • Keep the machine's own configuration out of the test suite (#303) (3bd9dfe)
  • Stop a mistyped concurrency from hanging the run and then panicking (#305) (a46c1bc)
  • Stop tying requests in flight to the core count (#306) (07eefcc)
  • Date a batch's newer releases in parallel, not one after another (#313) (4bdd2f2)
  • Count a batched fetch as a fetch, not as a cache hit (#314) (e8e7b75)
  • ci: Release the version that was asked for, even with no new commits (#315) (3134602)

Performance

  • Share one HTTP agent so connections are reused (#301) (c186101)
  • Ask prefix.dev about ten packages per request (#309) (d7fd067)

1.4.0 - 2026-10-03

Features

  • Let the configuration file choose the conda index (#286) (d8171ec)
  • Read system and user configuration from pixi's directories (#289) (fa3dcd8)

Bug Fixes

  • Confirm a mirrored package's channel by its hash, not its name (#281) (82df2d1)
  • Match the installed build by its build string, not by scanning a page (#283) (e0c1f19)
  • Stop blaming credentials for an answer the probe asked for (#290) (f428509)

Performance

  • Resolve a mirrored channel once, not once per package (#282) (c05ed68)

1.3.0 - 2026-10-02

Features

  • Read the credentials pixi already keeps, for a private channel (#278) (60a93c4)
  • Say which credentials a request carried, and fill in the trace level (#279) (c1ccaeb)

1.2.0 - 2026-10-02

Features

  • --conda-index-kind, with prefix.dev as a second conda index (#275) (1a79188)

Bug Fixes

  • A named conda index is asked about every channel, not only anaconda.org (#274) (2847ee2)
  • Prefix.dev dates are the build's own, and selecting an index lifts the filter (#276) (85a1059)

1.1.0 - 2026-10-01

Features

  • --doctor on its own probes every upstream it knows about (#262) (ae13c63)
  • PIXI_SBOM_CONDAPKG_URL, with the anaconda spelling kept permanently (#266) (4662b2a)
  • Point every upstream at a mirror, archives included (#271) (94dfe38)
  • --doctor probes the archive hosts, from the lockfile when there is one (#272) (af67224)

Bug Fixes

  • --doctor names the conda index by its role, not by a hostname (#264) (115d2b2)

Documentation

  • The strict attestation check, pinning the release workflow and tag (#246) (3235948)
  • A 20-second terminal recording at the top of the README (#249) (ee4b5c8)
  • A recording per report in the docs, and make them actually offline (#251) (2b56ded)
  • Document the Marketplace listing now that it exists (#253) (62f11db)
  • The real numbers in architecture.md, and the modules it left out (#255) (859c95b)
  • The site footer says Apache-2.0, which is what the project is (#258) (153947e)

1.0.0 - 2026-09-27

Features

  • --root-name and --outdated-min, with the old spellings kept (#227) (#228) (d45eb61)
  • Record vulnerabilities in SPDX 3.0.1 via the security profile (#118) (#229) (7b05001)
  • action: A floating v0 tag for Marketplace users, and docs that use it (#231) (238f41f)

Bug Fixes

  • docs: The config keys on the stability page were in a casing the parser rejects (#242) (62533ab)
  • Settle the support policy and harden the tag move before 1.0 (#244) (#245) (a48d23e)

Documentation

  • Write down what 1.0 freezes, and make the page check itself (#230) (98a068d)
  • The 1.0 pass over the docs, and somewhere for release copy to live (#119) (#241) (69db880)

Testing

  • Check the stability page in both directions, not just one (#232) (18ab185)

0.12.0 - 2026-09-27

Bug Fixes

  • ci: Attest releases from the tag so the provenance names what was built (#218) (#220) (88a368a)
  • --no-cache and --refresh now reach the archive caches (#197) (#224) (086cabf)
  • ci: Dogfood the action on every platform it claims to support (#225) (#226) (dd6e51c)

Documentation

  • A verify command that works, and stop shipping a perf dump (#222) (#223) (89d1613)

0.11.0 - 2026-09-27

Features

  • Support every lockfile format pixi has written, and say so (#206) (0ef9dd1)
  • Sign build provenance for every release archive (#202) (#213) (ee6cfb9)

Bug Fixes

  • The MSRV was never 1.85, and nothing was checking (#208) (e13fe1e)
  • docs: Move the site toolchain to PyPI to clear PYSEC-2026-2132 (#211) (#216) (68f6747)
  • A purl with no version is a name, not an identity (#215) (#217) (05fc3c8)

Documentation

  • The two presentations, and where their numbers come from (#199) (e545a70)
  • The published library is not an API, and now says so everywhere (#210) (e9f90b4)
  • A security policy, and a private way to report (#203) (#214) (1fb683e)

0.10.1 - 2026-09-26

Performance

  • Buffer stdout, which a milestone of benchmarks never looked at (#195) (d49c545)

CI and Build

  • perf: The memory gate goes back to 15% (#196) (2a7779e)

0.10.0 - 2026-09-26

Features

  • A criterion benchmark suite, and a library to point it at (#185) (04aea1a)
  • One pool on rayon, sized by PIXI_SBOM_CONCURRENCY (#186) (efc8f77)
  • Look every document's packages up once, not once per document (#187) (dcb6cb5)

Bug Fixes

  • perf: Measure the child, gate on a share and an amount, and record the allocator trade (#192) (0f37f8c)

Performance

  • Write documents straight out, and bound the license text a document holds (#188) (6f9dc2a)
  • A smaller, faster binary — panic=abort and mimalloc (#189) (64fe6ec)

CI and Build

  • Measure performance on every platform a binary is built for (#191) (c4a0f30)

0.9.5 - 2026-09-26

Features

  • Log every request and the whole error chain behind a failure (#164) (a6c3f31)
  • Give every diagnostic a help line naming the next step (#166) (4a3fc07)
  • Say which input and which settings a run chose (#167) (9764b1b)
  • Say what a run will talk to before it talks to anything (#168) (cd0a6c2)
  • Say where every fact about a package came from with --explain (#171) (b587acf)
  • --refresh and --no-cache, and say what each cache served (#170) (e25aa50)
  • --doctor probes every upstream and says which one is unreachable (#173) (59f15bb)
  • Name every gate that fired and the one that chose the exit code (#169) (ced2368)
  • --version-details prints what a bug report needs (#176) (e464c30)
  • Record in the document when enrichment was incomplete (#160) (#179) (711ed3e)
  • An empty vulnerability table says whether anything could be asked (#174) (157c9b5)
  • --timings says where the run spent its time (#177) (e0f2175)
  • --log-format json, for a collector rather than a person (#181) (5d65d99)
  • SOCKS and Windows system proxies, and a private CA bundle (#183) (70ce8f3)

Bug Fixes

  • Build the Pages artifact from mike's own commit (#165) (6dcaadf)
  • Close describe_input, which a rebase resolution dropped (#172) (1466b9f)
  • doctor: Count a body past the probe's read cap as an answer (#178) (9fe2c02)
  • One stale-cache tally, not two (#180) (5d76c11)

Documentation

  • List --doctor in the README options and examples (#175) (34c3c36)
  • What each log level says, and how to narrow it to one module (#182) (e5b4f38)

0.9.0 - 2026-09-25

Features

  • Render report tables with comfy-table and colour them with --color (753b37d)
  • Show progress bars while the enrichment fetches run (e0b4311)
  • Flag yanked PyPI releases and gate on them with --fail-on-yanked (cd1f60f)
  • Report how far behind its index each package is (3b1890f)
  • Report which packages cap the interpreter with --report python (#135) (e46854c)
  • Mark the dependencies the workspace declared itself (#136) (a4da5b6)
  • Name phantom, undeclared and unused dependencies with --report phantom (#137) (a358b9d)
  • Gate a run on what changed with --fail-on-diff (#138) (28a00f9)
  • Compare an installed environment with its lockfile (#139) (8492623)
  • Describe every workspace in a tree with --scan (#140) (f9cd174)
  • Read an existing document with --from-sbom (#141) (2d47b0f)
  • Exempt a package from the license policy with --ignore-license (#142) (d98e1b2)
  • Write the assessments as a standalone VEX with --vex (#143) (8a019c7)
  • Draw the dependency tree and group the licenses view (#144) (6a428f3)
  • Read the cargo auditable crate list out of installed binaries (#145) (569c6de)
  • Record the OpenSSF Scorecard of each package with --scorecard (#146) (81c7242)

Bug Fixes

  • Expire the docs repository card cache so it shows the current release (d075ffe)
  • Publish the crate from a clean checkout of the release tag (d5de240)
  • Keep the batch heading plain in the markdown report (c9e12a5)

Performance

  • Look PyPI licenses up ten at a time (69735f3)

0.8.0 - 2026-09-21

Features

  • Sign the documents with a GitHub artifact attestation from the action (370adbe)
  • Support cargo binstall and publish the crate from the release workflow (900391a)

0.7.0 - 2026-09-21

Features

  • Leave packages out with --exclude, --include and --exclude-kind (9a5cd54)
  • Read settings from pixi-sbom.toml or [tool.pixi-sbom] before the command line (381a4ec)
  • Report what changed since a previous document with --report diff --against (d81c832)
  • Describe an installed environment without a lockfile with --prefix (4336163)

0.6.0 - 2026-09-21

Features

  • Version the docs per release tag with a dev build from main (6f627aa)
  • Look up known vulnerabilities on OSV with --vulnerabilities osv (8c08627)
  • Add --report vulnerabilities in table, markdown, csv and json (9c2f910)
  • Gate on vulnerabilities with --fail-on-severity and accept them with --ignore-vuln (a4c4aab)
  • Flag findings in CISA's Known Exploited Vulnerabilities catalog with --kev (175b38d)
  • Write vulnerabilities as SARIF and expose the vulnerability flags in the action (0262b24)

Bug Fixes

  • Keep the pixi-sbom cache inside the pixi cache directory (d4b692e)

Documentation

  • Note the github-pages environment tag policy releases need (7519e49)

0.5.5 - 2026-09-21

Features

  • Scaffold the MkDocs documentation site (ce1a365)
  • Publish the documentation site to GitHub Pages on every release (68142af)
  • Link the documentation site and make the action Marketplace-ready (12c0df4)
  • Version the documentation site per release with mike (094dbfc)

Documentation

  • Restructure the site into installation, CLI, action, recipes and formats pages (9d88ab3)

0.5.1 - 2026-09-21

Features

  • Say why a license is not an SPDX expression (0280c50)
  • Read small .tar.bz2 archives whole for license details (29a13a7)

Bug Fixes

  • Capture the pixi-sbom exit status in the action under bash -e (a926a1e)
  • Let the action run more than once per job (1a718e5)
  • Keep conda-forge's "WITH exceptions" licenses as evaluable expressions (003339a)

0.5.0 - 2026-09-21

Features

  • Add a license policy gate with --allow-license, --deny-license and --require-license (1b0cf29)
  • Add a GitHub Action that runs the release binary (012e98c)
  • Write SPDX 3.0.1 JSON-LD with --format spdx --spec-version 3.0 (2bcfdf4)
  • Attach PEP 770 embedded SBOMs from wheels with --embedded-sboms (9ac664b)

0.4.0 - 2026-09-20

Features

  • Add --fetch-licenses with conda details from the package cache (23a8667)
  • Add --report to print package and license tables to the terminal (8d74219)
  • Read conda license details from channel archives by HTTP range (77a8597)
  • Read PyPI license details from wheels by HTTP range (96099b0)

Bug Fixes

  • Pin the report table width in snapshot tests (21444c3)
  • Make the archive e2e test independent of line endings and drive letters (eaa67ba)
  • Render local package paths as file URLs in the document (96ce0ba)
  • Emit LicenseRef licenses with texts as named licenses in CycloneDX (1f20b41)

0.3.0 - 2026-09-19

Features

  • Enrich conda packages with PyPI purls so scanners can match them (85ffd58)
  • Look up PyPI licenses from the index with --pypi-licenses (2a0f0de)
  • Write CycloneDX 1.7 with --spec-version (8b13136)

0.2.0 - 2026-09-19

Features

  • Derive deterministic document ids and honor SOURCE_DATE_EPOCH (cc72a3e)
  • Write the SBOM to stdout with --output - (fc1c83f)
  • Add --all-platforms, symmetric with --all-environments (9dcd06e)
  • Cover CISA 2026 minimum elements (07c8c5a)
  • Link PyPI packages to the conda python package (fac06fd)

Bug Fixes

  • Record the lockfile by name instead of its absolute path (3628bda)

0.1.0 - 2026-09-18

Features

  • Scaffold pixi-sbom Rust extension with CLI and lockfile discovery (eecca4b)
  • Build format-agnostic SBOM model from pixi.lock (899cbe9)
  • Write CycloneDX 1.6 and SPDX 2.3 JSON documents (b35464d)
  • Describe pixi-build source packages from their build source (efabe43)
  • Add --all-environments to write one SBOM per environment (9aadfe2)

Bug Fixes

  • ci: Replace retired macos-13 runner with macos-15-intel (5d80602)

Documentation

  • Add release workflow, conda-forge recipe, and field mapping docs (f6157b4)
  • Add usage, output format, architecture, and development guides (36368d4)

CI and Build

  • Run the test and build matrix on the -latest runners only (a0084aa)
  • Add two-stage release workflow that maintains CHANGELOG.md with git-cliff (e87c9ed)
  • Collapse release into a single App-token workflow (447f08c)